Artificial intelligence has definitively evolved from an experimental technology into a fundamental architectural component of enterprise systems. Large enterprises and critical infrastructure operators are implementing intelligent agents for data analysis, business process automation, and decision-making support. However, integrating AI into the corporate environment creates new threat vectors that cannot be mitigated by classic antivirus tools or simple restrictions on web resource access.
The main challenge for modern CISO and CTO roles is that AI services are often implemented outside established IT policies. Without proper system integration, isolated "shadow AI" zones emerge, functioning in bypass of corporate security standards and ignoring established Zero Trust rules, role-based access control (RBAC), and centralized audit systems.
Why "AI security" is a myth, and secure AI architecture is reality
Attempting to treat artificial intelligence as a separate "super-threat" and creating isolated protection perimeters for it is a misguided path that leads to ineffective, point-solution tools. Security for systems using AI is achieved by integrating AI components into the overall enterprise IT architecture at the level of strict data flow control.
The main problem lies not so much in the vulnerability of the algorithms themselves, but in the lack of control over what data the AI model consumes and generates within the corporate network. For example, employees using unauthorized public LLM services to process work documents accounts for 53.7% of incidents related to confidential information leakage via AI, while direct attacks on model algorithms account for about 27.7%. If a model has uncontrolled access to internal data repositories or users send sensitive information to external servers without authorization, a critical compliance risk arises.
The solution is to subject AI services to basic platform security rules: micro-segmentation, row-level security (RLS), and end-to-end logging.
NIST AI RMF 1.0 framework: integrating risks into corporate governance
To build a reliable artificial intelligence risk management system, leading organizations rely on the NIST AI RMF 1.0 standard. This framework structures the AI risk management lifecycle around four continuous functions:
- Govern: Creating an organizational culture of security where AI risks are integrated into the overall corporate governance model. This directly resonates with the NIST CSF 2.0 standard, which introduced the "Govern" function to confirm that cyber risks are an integral part of business strategy.
- Map: Identifying the context of AI usage, involved models, and data sources. Especially for critical infrastructure, NIST emphasizes the need to evaluate the context of application, potential harm, reliability, security, and accountability, rather than focusing solely on algorithm accuracy.
- Measure: Developing metrics for risk assessment and continuous analysis of algorithm and system quality for signs of manipulation or leaks.
- Manage: Implementing practical controls and incident response systems during AI operation.
AI risk management is not a one-time audit, but a continuous process that requires constant adaptation to new scenarios of user interaction with models.
Practical implementation: Zero Trust and RBAC for corporate AI agents
To neutralize threats from corporate AI tools, it is necessary to apply fundamental architectural security principles:
1. Granular access control (RBAC and RLS). When an AI assistant (e.g., for analytics or search) is integrated into a system, it should not have monolithic access to all databases. AI responses must be based only on documents to which the current user has legitimate access according to their role (RBAC) and security policy at the row level (RLS).
2. Integration of AI logs into centralized audit systems. Every prompt, generated response, and action by an AI agent must be recorded in a secure audit trail. This ensures accountability and timely detection of anomalous activity by corporate SIEM systems.
3. Zero Trust principles and human-in-the-loop. Model access to internal APIs must be limited to the minimum set of necessary permissions. No AI is "trusted" by default. For transactions or critical data changes, a human verification mechanism is mandatory.
Maturity matrix: how to evaluate artificial intelligence risk management
To assess corporate control over AI technologies, it is advisable to use a maturity scale based on the requirements of the AI management system (AIMS) standard — ISO/IEC 42001.
| Maturity level | State and process description |
|---|---|
| Level 1: Chaotic (Shadow AI) | Employees use public LLMs without control; corporate data leaks to external servers; no request monitoring. |
| Level 2: Reactive (Basic control) | Internal API gateways for AI created; access limited by general network rules; basic traffic logging without context analysis. |
| Level 3: Managed (NIST AI RMF / ISO 42001) | AI models integrated into the corporate IAM system; RBAC and micro-segmentation implemented; risks assessed at Map and Measure stages. |
| Level 4: Optimized (Built-in security) | AI agents operate in a secure perimeter with row-level security (RLS); automated audit trail records all actions; security is part of the platform architecture. |
Intecracy Group architectural approach: secure AI integration on the UnityBase platform
The development of custom software solutions with AI and AI consulting provided by Softengi (a member of the Intecracy Group technology alliance) is based on the principles of Security by Design. Softengi is certified to the international AI management standard ISO/IEC 42001:2023, which confirms a responsible and structured approach to managing the development of artificial intelligence systems.
To avoid creating isolated protection tools and to seamlessly integrate AI into the existing IT landscape, the low-code platform UnityBase is used as the technological foundation. UnityBase is a joint development by the companies of the Intecracy Group alliance (InBase acts as a key, but not the sole, developer of the platform), created specifically for building high-load enterprise applications with strict security requirements.
Using the mechanisms of the UnityBase platform provides solutions with integrated AI a number of architectural advantages:
- Domain metadata as the foundation of security: A unified domain model ensures that security rules are automatically applied to any data accessed by an AI module.
- Built-in row-level security (RLS): An AI agent is technically unable to access a database record if the current user does not have permission for it. This eliminates horizontal privilege escalation.
- Strict audit trail: The platform ensures end-to-end logging of data operations. Any AI action is recorded in the system with the ability to clearly trace the chain of requests.
- Data isolation: Support for on-premises deployment (including Enterprise and Defence commercial editions) allows for the operation of local LLM models entirely within the secure enterprise perimeter, neutralizing risks of cross-border data transfer.
A clear example of this approach is DMS and ECM class systems, such as Scriptum.DMS and Megapolis.DocNet. Because these products are built on the UnityBase platform, the AI modules integrated into them (AI centers) function in a strictly controlled environment, adhering to corporate access policies.
Artificial intelligence security is not a separate product, but a mature engineering process where AI is viewed as an organic part of a single corporate ecosystem, managed by proven frameworks and built-in architectural mechanisms of the platform.
FAQ
How to integrate AI services into an existing enterprise Zero Trust system?
Integration is carried out by depriving AI components of direct, uncontrolled access to databases. AI agents must interact with data exclusively through secure API gateways, subject to the corporate IAM system, where role-based access control (RBAC) and row-level security (RLS) policies are in effect.
Which NIST AI RMF 1.0 standard requirements are key for critical infrastructure?
For critical infrastructure, the standard requires going beyond assessing the technical accuracy of a model. The main emphasis is placed on the Map function: mandatory assessment of the context of application, potential harm, reliability, model security, and ensuring the accountability of decision-making processes.
How to prevent confidential data leaks through internal corporate LLM assistants?
It is necessary to implement an architecture that supports on-premises deployment of models within a secure perimeter, apply strict access control to data sources (e.g., via RLS), and ensure end-to-end logging of all AI actions (audit trail) for continuous anomaly monitoring.
Data sources
- NIST: Artificial Intelligence Risk Management Framework (AI RMF 1.0)
- NIST Cybersecurity Framework (CSF) 2.0
- vertexaisearch.cloud.google.com: Стратегічний підхід до управління ризиками штучного інтелекту - BDO Україна
- vertexaisearch.cloud.google.com: Управління ризиками ШІ в критичній інфраструктурі: NIST AI RMF 1.0 - UA Software
- vertexaisearch.cloud.google.com: Як перетворити ШІ без ризиків на союзника в галузі кібербезпеки? - KPMG International
- vertexaisearch.cloud.google.com: АНАЛІЗ РОБОЧОГО ІНСТРУМЕНТАРІЮ УПРАВЛІННЯ РИЗИКАМИ ІНФОРМАЦІЙНОЇ БЕЗПЕКИ З ВИКОРИСТАННЯМ ТЕХНОЛОГІЙ ШТУЧНОГО ІНТЕЛ